NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87222 | CVE-2016-8751 | Apache Ranger before 0.6.is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies. | 2 | 3.5 | Low | 2017-06-23 | 2017-06-19 | View | |
87734 | CVE-2017-10921 | The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
87990 | CVE-2017-4054 | Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-17 | View | |
88246 | CVE-2017-9884 | IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-11 | View | |
28342 | CVE-2015-7974 | NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." | 2 | 2.1 | Low | 2017-05-27 | 2017-05-26 | View |
Page 1635 of 17672, showing 5 records out of 88360 total, starting on record 8171, ending on 8175